TL;DR: Ransomware delivery has shifted further toward email, with Abnormal AI citing a 600% increase in active ransomware groups since 2020 and saying over 76% of ransomware is delivered through email. That pattern makes inbox security, credential hygiene, and user-facing controls part of ransomware defence, not just detection.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Theresa Payton on Ransomware: Malware as an Ongoing Email Issue”.
By the numbers:
- Since the beginning of 2020, there has been a 600% increase in the number of active ransomware groups.
- Over 76% of ransomware is delivered through email.
Key questions
Q: How should security teams reduce ransomware risk from email-delivered attacks?
A: Treat email as an identity entry point, not just a messaging channel.
Q: Why does email-delivered ransomware increase identity risk as well as malware risk?
A: Because the first security failure is often a trust decision made by a user with valid access.
Practitioner guidance
- Harden inbox trust boundaries Deploy stronger authentication, attachment inspection, and URL controls so malicious email content is less likely to reach users as trusted content.
- Correlate email and identity signals Feed suspicious message events, user clicks, and abnormal login activity into the same detection path so one message can be tied to account abuse.
- Reduce user-facing exposure to high-risk inboxes Apply tighter controls for roles that receive external mail at volume, especially where a single account compromise would create broad access.
Bottom line: Email-delivered ransomware is a control problem, not just a malware problem, because the first compromise often begins with user trust.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email is no longer just a delivery channel, it is an access-control problem. When more than three quarters of ransomware arrives through email, the control objective shifts from message hygiene to identity-bound containment. Inbox filtering, authentication signals, and user trust all become part of the same failure domain. The practical conclusion is that email security and IAM can no longer be managed as separate programmes.
A question worth separating out:
Q: How can email security fit into identity governance more effectively?
A: Email security should feed identity-aware response, not sit apart from it. If a suspicious message leads to credential theft, mailbox abuse, or account takeover, the control value lies in how quickly the organisation can investigate, contain, and review access. That makes integration with identity workflows as important as detection quality.
👉 Read our full editorial: Ransomware delivered through email is accelerating enterprise risk